Back to skill

Security audit

failure-forensics

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent failure-analysis helper, but users should treat analyzed logs and generated reports as sensitive.

Install only if you are comfortable giving the agent access to failure logs you select. Redact tokens, credentials, private paths, customer data, and confidential prompts before generating or saving reports, and store post-mortems only in approved access-controlled locations. Treat generated Markdown as untrusted if logs came from external or attacker-influenced systems.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/failure_forensics.py:323
Finding

Unescaped Log Data Permits Markdown Report Injection

Content
View full analysis
80 else (call.error or "") timeline_rows.append(f"| {i} | {ts} | `{call.tool}` | {outcome} | {err} |") ``` ```python return POST_MORTEM_TEMPLATE.format( title=title, date=now, author=author, primary_category=primary_category, total_calls=summary["total_calls"], failed_calls=summary["failed_calls"], first_failure_tool=summary["first_failure_tool"] or "N/A", first_failure_error=(summary["first_failure_error"] or "N/A")[:200], first_failure_category=summary["first_failure_category"] or "uncategorized", timeline_table=timeline_table, ) ``` ### Technical Analysis The report generator directly interpolates data from analyzed logs into Markdown table cells, inline-code spans, headings, and template fields. The affected values include the tool name, error message, report title, and author. These values are not escaped or normalized before insertion. An attacker-controlled error message or tool name can c ...[truncated 2041 chars]
Remediation
View remediation
str: text = str(value) text = text.replace("\\", "\\\\") text = text.replace("|", "\\|") text = text.replace("\r", " ").replace("\n", " ") text = text.replace("`", "\\`") return text ``` 3. Apply the helper to every untrusted value inserted into timeline tables, including `call.tool`, `call.error`, and any derived category text. 4. Validate and sanitize report metadata such as `title` and `author`. Restrict them to a single line and escape Markdown metacharacters before template interpolation. 5. If raw HTML is unnecessary, strip or encode HTML delimiters before writing the report. Where possible, configure the downstream renderer to disable raw HTML. 6. Add regression tests covering: - Pipe characters such as `| forged cell |` - Embedded backticks - Carriage returns and newlines - Markdown headings and links - Raw HTML tags - Combined payloads that attempt to escape both inline-code and table contexts 7. Verify remediation by generating both timeline and post-mortem output from adversarial JSONL fixtures and confirming that all input remains inert text within its intended field. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code substantially matches much of the declared description: it analyzes tool-call logs, categorizes failures, finds failures in the timeline, and generates a post-mortem report. However, key declared capabilities are not actually implemented. There is no mechanism to reconstruct a decision chain beyond listing tool calls in time order, no true root-cause analysis beyond regex-based error categorization and first-failure detection, and no functionality to save lessons learned for future prevention. Because these are central parts of the declared purpose rather than minor details, this is a meaningful description/behavior mismatch, though not a complete mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read logs, generate reports, and persist artifacts, which implies file read/write access and potentially network-backed storage, yet it declares no explicit tool scope. This weakens least-privilege controls and can cause the skill to run with broader capabilities than reviewers or policy systems expect, increasing the chance of unintended data access or exfiltration through saved reports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages collecting tool-call logs and saving post-mortem artifacts without warning that such logs commonly contain secrets, tokens, file paths, internal hostnames, prompts, and user data. Persisting or sharing these artifacts unredacted can leak sensitive information into durable storage, issue trackers, or knowledge bases where access is broader and retention is longer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example explicitly recommends saving reports to durable locations such as issue trackers or knowledge bases without any privacy or data-handling warning. In failure analysis contexts, those reports often aggregate raw error text and timeline details that can expose secrets or internal system information to wider audiences than the original execution context.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/failure-taxonomy.md (reported line 76)May include surrounding context.

md
- Token expired and wasn't refreshed
- Token has correct identity but wrong scope/role
- File owned by a different user; agent running as non-root
- sudo / privilege escalation required but not available
- IAM policy missing a specific action (e.g., `s3:GetObject` but not `s3:PutObject`)

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/post-mortem-template.md (reported line 57)May include surrounding context.

md
2. **Because:** npm attempted a global install (no `--prefix` or local `package.json`)
3. **Because:** The agent assumed the install target was local, but the working directory had no `package.json`
4. **Because:** The agent didn't verify the working directory contents before running the install
5. **Because:** The task description referenced a project at a path the agent assumed existed without checking ← **ROOT CAUSE**

**Root cause:** The agent operated on an unverified assumption about the filesystem state (project path) and cascaded into a permissions failure that looked like an environment problem.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tool writes a Markdown timeline derived directly from tool-call logs to an arbitrary output path without any warning, redaction, or consent gate. Since tool-call logs can contain secrets in arguments, error strings, timestamps, and operational context, this can persist sensitive data to disk where it may be retained, indexed, shared, or committed unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The post-mortem report includes first-failure error text and a timeline of tool activity generated from logs, then writes that content to disk without any safeguards. In the context of a failure-forensics skill, logs are especially likely to contain stack traces, API errors, command arguments, and other sensitive debugging artifacts, increasing the chance of confidential data exposure through stored reports.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/sample_log.jsonl (reported line 3)May include surrounding context.

text
{"timestamp": "2024-01-15T10:23:01Z", "tool": "terminal", "args": {"command": "git clone https://github.com/example/repo.git"}, "result": {"success": true, "output": "Cloning into 'repo'..."}, "duration_ms": 3400}
{"timestamp": "2024-01-15T10:23:10Z", "tool": "terminal", "args": {"command": "cd repo && npm install"}, "result": {"success": false, "error": "EACCES: permission denied, open '/usr/lib/node_modules/lodash'"}, "duration_ms": 1200}
{"timestamp": "2024-01-15T10:23:15Z", "tool": "terminal", "args": {"command": "sudo npm install"}, "result": {"success": false, "error": "sudo: a password is required"}, "duration_ms": 100}
{"timestamp": "2024-01-15T10:23:20Z", "tool": "web_search", "args": {"query": "npm EACCES permission denied fix"}, "result": {"success": true}, "duration_ms": 800}
{"timestamp": "2024-01-15T10:23:30Z", "tool": "terminal", "args": {"command": "npm install --prefix ~/.local"}, "result": {"success": false, "error": "ConnectionRefusedError: connect ECONNREFUSED 127.0.0.1:443"}, "duration_ms": 5000}
{"timestamp": "2024-01-15T10:23:40Z", "tool": "terminal", "args": {"command": "curl https://registry.npmjs.org/"}, "result": {"success": false, "error": "curl: (7) Failed to connect to registry.npmjs.org port 443: Connection timed out"}, "duration_ms": 30000}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly describes parsing tool-call logs and saving post-mortem reports/lessons, but it does not warn that such logs may contain secrets, credentials, command arguments, tokens, file paths, or user data. In a failure-analysis skill, aggregating and persisting debugging artifacts increases the chance of secondary disclosure if sensitive fields are not redacted before analysis or storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.